Application security

Signal contact discovery service vulnerabilities allowed enclave escape

The Signal app icon on a smartphone.

Based on information from Cyber Insider, security researchers have discovered critical vulnerabilities in Signal’s Contact Discovery Service that could allow a malicious server operator to bypass protections offered by its Intel SGX enclave.

Researchers at V12 identified two flaws in Signal's Contact Discovery Service (CDSI), which is designed to help users find contacts on Signal without revealing their address book to the service. The vulnerabilities, found in the Intel SGX enclave used for sensitive processing, could permit arbitrary reading of protected memory and, in a more severe case, code execution within the trusted environment. The first flaw involved a race condition allowing a malicious host to read enclave memory, potentially enabling impersonation and decryption of queries. The second vulnerability, a time-of-check-to-time-of-use flaw, could allow an attacker to gain control over the enclave's CPU and execute arbitrary code.

V12 developed working exploits and tested them on hardware matching Signal's production environment. Signal has since patched both vulnerabilities by enforcing single workers per shard and combining validity checks into atomic operations. As the fixes were applied server-side, users do not need to take action beyond keeping their Signal app updated.

Source: Cyber Insider

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds